[ipv6hackers] thc-ipv6 v3.0, IPv6 complexity and evasions

Gert Doering gert at space.net
Tue Oct 20 09:17:59 CEST 2015


Hi,

On Mon, Oct 19, 2015 at 09:42:19PM -0300, Fernando Gont wrote:
> > (I do observe issues with UDP fragments here, as FreeBSD's pf is
> > still too stupid to properly handle them, and some things work slower
> > as a consequence, and others don't work at all - like, TCP through a
> > Netscreen NAT64, which will emit atomic fragments...)
> 
> Including atomic fragments in the NAT64 was bad design, IMO.
> Particularly when the spec itself acknowledged that they don't work.

I totally agree - but still, until vendors upgrade their NAT64 implementations
to no longer use them, I'll have to live with them...

Gert Doering
        -- NetMaster
-- 
have you enabled IPv6 on something today...?

SpaceNet AG                        Vorstand: Sebastian v. Bomhard
Joseph-Dollinger-Bogen 14          Aufsichtsratsvors.: A. Grundner-Culemann
D-80807 Muenchen                   HRB: 136055 (AG Muenchen)
Tel: +49 (0)89/32356-444           USt-IdNr.: DE813185279


More information about the Ipv6hackers mailing list